GDPR Statement
Last updated: April 2026
StefSite is committed to compliance with the EU General Data Protection Regulation (Regulation 2016/679) and equivalent UK legislation. This statement explains how we meet those obligations. It complements our Privacy Policy.
1. Data controller
StefSite acts as the data controller for personal data submitted through StefSite.com. For all GDPR matters, contact:
2. Lawful basis for processing
We rely on the following lawful bases under Article 6 GDPR:
- Consent (Art. 6(1)(a)) — when you voluntarily submit your URL and email through our form to receive a redesign preview.
- Contract (Art. 6(1)(b)) — when we process data to deliver a paid website project to you.
- Legitimate interest (Art. 6(1)(f)) — for security logs, fraud prevention, and limited business outreach to publicly listed companies, where our interests don't override your rights.
- Legal obligation (Art. 6(1)(c)) — for invoicing, tax retention, and responding to lawful requests from authorities.
3. Your rights as a data subject
You have the following rights, free of charge:
- Right of access (Art. 15) — get a copy of the data we hold about you.
- Right to rectification (Art. 16) — have inaccurate data corrected.
- Right to erasure (Art. 17) — request deletion of your data.
- Right to restrict processing (Art. 18) — limit how we use your data.
- Right to data portability (Art. 20) — receive your data in a machine-readable format.
- Right to object (Art. 21) — object to processing based on legitimate interest.
- Right to withdraw consent (Art. 7(3)) — at any time, without affecting prior lawful processing.
- Right not to be subject to automated decisions (Art. 22) — we do not make legally significant decisions about you using automated processing.
4. How to exercise your rights
Email privacy@stefsite.com with your request. To protect your data, we may ask you to confirm your identity. We respond within 30 days, as required by Article 12. If your request is complex, we may extend by an additional two months and notify you of the reason.
5. Data retention
- Prospect submissions: 12 months
- Client project data: duration of relationship + 7 years (legal/tax retention)
- Server logs: 30 days
- Marketing emails: until you unsubscribe
6. International transfers
Where personal data is transferred outside the European Economic Area — for example to AI providers based in the United States — we rely on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and additional safeguards where required.
7. Data breaches
In the event of a personal data breach likely to result in a risk to your rights or freedoms, we will notify the competent supervisory authority within 72 hours and, if the risk is high, notify affected individuals without undue delay (Articles 33–34).
8. Right to lodge a complaint
If you believe we've mishandled your data, you have the right to file a complaint with your local data protection authority. For Dutch residents, this is the Autoriteit Persoonsgegevens. A list of all EU authorities is available on the European Data Protection Board website.
9. Data Protection Officer
As a small organization, we are not legally required to appoint a Data Protection Officer under Article 37. Privacy matters are handled directly by the founders. For any GDPR question, write to privacy@stefsite.com.